Investigating threats with Azure Security Center
In Chapter 11, Security Monitoring and Reporting, we enabled and configured the standard version of Azure Security Center to gain the benefits of all the available premium features. ATP is part of the standard feature for your Azure environment, including your Windows machines. To view and investigate any threats that have been triggered by Azure Security Center, do the following:
- Log in to https://portal.azure.com.
- Search for Security Center and open it.
- Click on Security Alerts within the Threat Protection section.
- Here, you will see all the generated alerts from your environment:
To further investigate an alert, simply click on the alert and you are provided with additional details. In addition, you will be provided with any available remediation steps by scrolling further down the details page. The following is an example of the details...